CVE-2024-33506
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Oct 8, 2024
Updated: Jan 21, 2025
CWE ID 200
Summary
CVE-2024-33506 is a vulnerability affecting FortiManager versions 7.4.2 and below, 7.2.5 and below, and 7.0.12 and below. This issue, categorized as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), enables a remote, authenticated attacker with access to an Administrative Domain (ADOM) to gain unauthorized access to the device summary information of other unauthorized ADOMs through carefully crafted HTTP requests.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- FortiManager
Affected Vendors
- Fortinet